ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ26ÖÜ
Ðû²¼Ê±¼ä 2018-07-02Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2018Äê06ÔÂ25ÈÕÖÁ29ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´55¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇSchneider Electric U.motion BuilderÕ»»º³åÇøÒç³ö©¶´£»Delta Industrial Automation COMMGR AHSIM_5x0 SimulatorÕ»»º³åÇøÒç³ö©¶´£»Adobe Reader DCÔ½½ç¶ÁÈÎÒâ´úÂëÖ´ÐЩ¶´£»Microsoft OneDrive DLL´¦ÖÃÈÎÒâ´úÂëÖ´ÐЩ¶´£»Apache HBaseÄþ¾²ÏÞÖÆÈƹý©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÑо¿ÈËÔ±¾¯¸æ³ÆʹÓÃTLSÈÏÖ¤ÍøÕ¾µÄNetflixµöÓã»î¶¯²»Í£Ôö³¤£»Ó¢¹úË°Îñ»ú¹ØHMRCÉæÏÓÎ¥·¨ÊÕ¼¯Ô¼510ÍòÓû§µÄÓïÒô¼Ç¼£»Wi-FiÁªÃËÕýʽÐû²¼ÐÂÒ»´úÄþ¾²³ß¶ÈWPA3£¬¿É½øÒ»²½Ìá¸ßÍøÂçÄþ¾²ÐÔ£»FastBookingÔâºÚ¿ÍÈëÇÖ£¬Êý°Ù¼Ò¾ÆµêµÄÓû§Êý¾Ýй¶£»FacebookµÚÈý·½Ó¦Óõ¼ÖÂÔ¼1.2ÒÚÓû§µÄÊý¾ÝÃæÁÙй¶·çÏÕ¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí
1¡¢Schneider Electric U.motion BuilderÕ»»º³åÇøÒç³ö©¶´
Schneider Electric U.motion Builder´æÔÚÕ»µÄ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://www.schneiderelectric.com/en/download/document/Umotion_Server_update/
2¡¢Delta Industrial Automation COMMGR AHSIM_5x0 SimulatorÕ»»º³åÇøÒç³ö©¶´
Delta Industrial Automation COMMGR AHSIM_5x0 Simulator´¦ÖÃTCP±¨ÎÄ´æÔÚÕ»Òç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔCOMMGR½ø³ÌÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttp://www.deltaww.com/Products/PluginWebUserControl/downloadCenterCounter.aspx?DID=2093&DocPath=1&hl=en-US
3¡¢Adobe Reader DCÔ½½ç¶ÁÈÎÒâ´úÂëÖ´ÐЩ¶´
Adobe Reader DC´æÔÚÔ½½ç¶Á©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄPDFÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-02.html
4¡¢Microsoft OneDrive DLL´¦ÖÃÈÎÒâ´úÂëÖ´ÐЩ¶´
Microsoft OneDrive´¦ÖÃËÑË÷·¾¶´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄDLL£¬ÓÕʹÓû§½âÎö£¬¿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://blogs.technet.microsoft.com/srd/2018/04/04/triaging-a-dll-planting-vulnerability/
5¡¢Apache HBaseÄþ¾²ÏÞÖÆÈƹý©¶´
Apache HBase´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÈƹýÄþ¾²ÏÞÖÆ£¬Ö´ÐÐδÊÚȨµÄ²Ù×÷¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://lists.apache.org/thread.html/a919e38f587c714c386a01d40fc8f45bd4219a65aaf2dc0bb4eccc96@%3Cdev.hbase.apache.org%3E
Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢Ñо¿ÈËÔ±¾¯¸æ³ÆʹÓÃTLSÈÏÖ¤ÍøÕ¾µÄNetflixµöÓã»î¶¯²»Í£Ôö³¤
SANS¼¼ÊõÑо¿ÔºÔº³¤Johannes Ullrich³ÆʹÓÃTLSÈÏÖ¤ÍøÕ¾µÄNetflixµöÓã»î¶¯²»Í£Ôö³¤¡£¹¥»÷ÕßÊ×ÏÈÈëÇÖWordPress»òDrupalµÈCMS¹¹½¨µÄÍøÕ¾£¬È»ºó´´½¨NetflixµöÓãÍøÕ¾²¢»ñÈ¡ÓëNetflixÃû³ÆÏà¹ØµÄTLSÖ¤Ê飬Èçnetflix.domain.com»ònetflix.login.domain.com£¬ÕâʹÆä¿´ÆðÀ´Ô½·¢¿ÉÐÅ¡£ËäÈ»NetflixÕË»§¼ÛÖµ²¢²»¸ß£¬µ«ÕâÖÖ¹¥»÷Ò×ÓÚʵÏÖ×Ô¶¯»¯ÇÒÄÑÒÔÈÃÊܺ¦Õß·¢ÏÖ¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/new-phishing-scam-reels-in-netflix-users-to-tls-certified-sites/132976/
2¡¢Ó¢¹úË°Îñ»ú¹ØHMRCÉæÏÓÎ¥·¨ÊÕ¼¯Ô¼510ÍòÓû§µÄÓïÒô¼Ç¼
Òþ˽±£»¤×éÖ¯Big Brother Watch·¢ÏÖÓ¢¹úµÄË°Îñ»ú¹ØHMRCÉæÏÓÎ¥·¨ÊÕ¼¯Ô¼510ÍòÓ¢¹ú¹«ÃñµÄÓïÒô¼Ç¼¡£HMRCͨ¹ý2017Äê1ÔÂÍƳöµÄÒ»ÏîÓïÒôʶ±ð·þÎñÊÕ¼¯ÁËÕâЩ¼Ç¼£¬¸Ã·þÎñÔÊÐíÓû§ÔÚºô½ÐHMRCʱͨ¹ýÓïÒô½øÐÐÉí·ÝÑéÖ¤¡£µ«Big Brother Watch·¢ÏÖÓû§ÎÞ·¨Ñ¡Ôñ²»Ê¹Óø÷þÎñ£¬ËùÓв¦´òHMRCÈÈÏßµÄÓû§¶¼±»ÆȼÖÆÁËÓïÒô¼Ç¼£¬¶øÇÒÓû§ÎÞ·¨Ñ¡Ôñ´ÓHMRCµÄÊý¾Ý¿âÖÐɾ³ýÆäÓïÒô¼Ç¼¡£¸Ã×éÖ¯ÈÏΪHMRC´Ë¾ÙÃ÷ÏÔÎ¥·´ÁËGDPR£¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©ÒѶԴËÊÂÕ¹¿ªÕýʽµÄÊӲ졣
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/uk-tax-agency-recorded-the-voices-of-51-million-brits/
3¡¢Wi-FiÁªÃËÕýʽÐû²¼ÐÂÒ»´úÄþ¾²³ß¶ÈWPA3£¬¿É½øÒ»²½Ìá¸ßÍøÂçÄþ¾²ÐÔ
±¾ÖÜÒ»Wi-FiÁªÃËÕýʽÐû²¼ÐÂÒ»´úÄþ¾²³ß¶ÈWPA3£¬WPA3ÊÇÓÃÓÚWi-FiÁ¬½ÓµÄÓû§Éí·ÝÑéÖ¤¼¼ÊõµÄ×îа汾¡£WPA3ÓÐÁ½ÖÖÄþ¾²Ä£Ê½£¬WPA3-PersonalºÍWPA3-Enterprise£¬ÕâÁ½ÖÖÄþ¾²Ä£Ê½µÄÖ÷ÒªÇø±ðÔÚÓÚÉí·ÝÑéÖ¤½×¶Î¡£¶ÔÓÚÆóÒµ¡¢Õþ¸®ºÍ½ðÈÚÍøÂçÖÐʹÓõÄÉ豸£¬½¨ÒéʹÓÃWPA3-EnterpriseÄþ¾²Ä£Ê½£¬WPA3-PersonalÔòÊÇÃæÏòÆÕͨ¸öÈËÓû§¡£Wi-FiÁªÃËÌåÏÖWPA3µÄSAEËã·¨Äܹ»µÖÓù±©Á¦¹¥»÷£¬WPA3½«ÔÚ¶à´Îʧ°ÜʵÑéºó×èÖ¹ÈÏÖ¤ÇëÇó¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-wpa3-wi-fi-standard-released/
4¡¢FastBookingÔâºÚ¿ÍÈëÇÖ£¬Êý°Ù¼Ò¾ÆµêµÄÓû§Êý¾Ýй¶
°ÍÀè¾ÆµêÔ¤¶©¹«Ë¾FastBookingÔâºÚ¿ÍÈëÇÖ£¬Êý°Ù¼Ò¾ÆµêµÄÓû§Êý¾Ýй¶¡£FastBooking³Æ¹¥»÷ÕßÔÚ6ÔÂ14ÈÕÀûÓÃÆä·þÎñÆ÷ÉÏÒ»¸öÈí¼þµÄ©¶´°²×°Á˶ñÒâÈí¼þ£¬²¢ÇÔÈ¡Á˾ƵêÓû§µÄÐÕÃû¡¢¹ú¼®¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·ºÍ¾ÆµêÔ¤¶¨Ïà¹ØÐÅÏ¢£¨¾ÆµêÃû³Æ¡¢ÈëסºÍÍË·¿£©µÈÊý¾Ý£¬ÇÔÈ¡µÄÊý¾Ý»¹°üÂÞ²¿ÃÅÓû§µÄÒøÐп¨ÐÅÏ¢£¬È翨ºÅ¡¢¹ýÆÚÈÕÆڵȡ£FastBooking³Æ¸ÃʼþÓ°ÏìÁËÈÕ±¾µÄ380¼Ò¾Æµê£¬Bleeping ComputerÈÏΪÕâÒ»Êý×ÖÔÚÈ«Çò·¶Î§ÄÚ¿ÉÄÜÁè¼ÝÁË1000¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hundreds-of-hotels-affected-by-data-breach-at-hotel-booking-software-provider/
5¡¢FacebookµÚÈý·½Ó¦Óõ¼ÖÂÔ¼1.2ÒÚÓû§µÄÊý¾ÝÃæÁÙй¶·çÏÕ
Ñо¿ÈËÔ±Inti De Ceukelaire·¢ÏÖµÚÈý·½ÖÇÁ¦¾ºÈüÓ¦ÓÃNametests.comʹԼ1.2ÒÚFacebookÓû§µÄÊý¾ÝÃæÁÙй¶·çÏÕ¡£Ö»ÒªFacebookÓû§ÔÚNameTestsÍøÕ¾ÉÏ×¢²á£¬¸Ã¹«Ë¾½«¿ÉÒÔ»ñÈ¡Óû§µÄ¸öÈËÊý¾Ý¡£µ«Ñо¿ÈËÔ±·¢ÏÖNameTestsÍøÕ¾´íÎóµØ½«Æä¡°Access-Control-Allow-Origin¡±¼ÆıÅäÖóÉͨÅä·û*£¬ÕâÔÊÐíÈκÎÍøÕ¾·ÃÎÊÆä×ÊÔ´£¬°üÂÞÕâЩÓû§µÄ¸öÈËÊý¾Ý¡£NameTestsÒѾÐÞ¸´Á˸ÃÎÊÌâ¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/facebook-users-data-leak.html
©ADLab ¶«Éƽ̨»ý¼«·ÀÓùʵÑéÊÒ 2016